The repository has no security policy, while its tests, licensing, and recent releases provide useful safeguards. Pin workflow actions before relying on its automation.
72%
Total Score
75
94
50
All 9 commits in the last 3 months came from one contributor, leaving maintenance dependent on a single active developer despite organization ownership.
No repository security policy was found, leaving vulnerability reporting and response expectations undocumented.
Version v0.2.2 is not a prerelease, but the project remains below 1.0, so its API may still change more readily than a mature stable-major package.
The workflow audit completed successfully with no dangerous triggers, untrusted checkouts, script injection, or high-confidence findings. However, all 18 action references are unpinned, which weakens build reproducibility and supply-chain control.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/container Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.